|
222401
|
5.5 |
MEDIUM
Local
|
djvulibre_project debian fedoraproject canonical opensuse
|
djvulibre debian_linux fedora ubuntu_linux leap
|
In DjVuLibre 3.5.27, the sorting functionality (aka GArrayTemplate<TYPE>::sort) allows attackers to cause a denial-of-service (application crash due to an Uncontrolled Recursion) by crafting a PBM im…
|
CWE-674
Uncontrolled Recursion
|
CVE-2019-15144
|
2024-11-21 13:28 |
2019-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222402
|
5.5 |
MEDIUM
Local
|
djvulibre_project debian fedoraproject canonical opensuse
|
djvulibre debian_linux fedora ubuntu_linux leap
|
In DjVuLibre 3.5.27, the bitmap reader component allows attackers to cause a denial-of-service error (resource exhaustion caused by a GBitmap::read_rle_raw infinite loop) by crafting a corrupted imag…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2019-15143
|
2024-11-21 13:28 |
2019-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222403
|
5.5 |
MEDIUM
Local
|
djvulibre_project debian fedoraproject canonical opensuse
|
djvulibre debian_linux fedora ubuntu_linux leap
|
In DjVuLibre 3.5.27, DjVmDir.cpp in the DJVU reader component allows attackers to cause a denial-of-service (application crash in GStringRep::strdup in libdjvu/GString.cpp caused by a heap-based buff…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-15142
|
2024-11-21 13:28 |
2019-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222404
|
6.5 |
MEDIUM
Network
|
imagemagick opensuse
|
imagemagick leap
|
WriteTIFFImage in coders/tiff.c in ImageMagick 7.0.8-43 Q16 allows attackers to cause a denial-of-service (application crash resulting from a heap-based buffer over-read) via a crafted TIFF image fil…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-15141
|
2024-11-21 13:28 |
2019-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222405
|
8.8 |
HIGH
Network
|
imagemagick
|
imagemagick
|
coders/mat.c in ImageMagick 7.0.8-43 Q16 allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly have unspecified other impact by crafting a Matlab ima…
|
CWE-416
Use After Free
|
CVE-2019-15140
|
2024-11-21 13:28 |
2019-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222406
|
6.5 |
MEDIUM
Network
|
imagemagick
|
imagemagick
|
The XWD image (X Window System window dumping file) parsing component in ImageMagick 7.0.8-41 Q16 allows attackers to cause a denial-of-service (application crash resulting from an out-of-bounds Read…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-15139
|
2024-11-21 13:28 |
2019-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222407
|
9.8 |
CRITICAL
Network
|
humanica
|
humatrix_7
|
The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to upload any file type to a candidate's profile picture folder via a crafted recruitment_onli…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2019-15130
|
2024-11-21 13:28 |
2019-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222408
|
5.3 |
MEDIUM
Network
|
humanica
|
humatrix_7
|
The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to access all candidates' files in the photo folder on the website by specifying a "user id" p…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-15129
|
2024-11-21 13:28 |
2019-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222409
|
7.5 |
HIGH
Network
|
eprosima
|
fast-rtps
|
The Access Control plugin in eProsima Fast RTPS through 1.9.0 allows fnmatch pattern matches with topic name strings (instead of the permission expressions themselves), which can lead to unintended c…
|
NVD-CWE-noinfo
|
CVE-2019-15137
|
2024-11-21 13:28 |
2019-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222410
|
7.5 |
HIGH
Network
|
eprosima
|
fast-rtps
|
The Access Control plugin in eProsima Fast RTPS through 1.9.0 does not check partition permissions from remote participant connections, which can lead to policy bypass for a secure Data Distribution …
|
CWE-862
Missing Authorization
|
CVE-2019-15136
|
2024-11-21 13:28 |
2019-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|